Job Summary:The Mid-Level Network Security Engineer is responsible for implementing, configuring, monitoring, troubleshooting, and maintaining network security solutions to ensure the security, availability, and performance of customer and internal network environments.
Responsibilities:Configure, implement, and maintain network security solutions, including:
- Firewalls
- VPN solutions
- Network Access Control (NAC)
- Intrusion Prevention/Detection Systems (IPS/IDS)
- Secure Web Gateways and related security solutions.
Perform firewall rule configuration, NAT, access policies, security profiles, and traffic filtering.
Configure and troubleshoot Site-to-Site VPN and Remote Access VPN connections.
Monitor network security devices, traffic, alerts, and logs to identify potential security incidents or abnormal activities.
Troubleshoot network connectivity and security-related issues and provide timely resolution.
Analyze network traffic and security logs to identify the root cause of incidents.
Perform configuration changes, upgrades, backups, and health checks for network security devices.
Support the implementation and commissioning of network security projects at customer sites.
Conduct technical assessments and assist in identifying network security requirements.
Prepare and maintain technical documentation, network diagrams, configurations, and implementation records.
Coordinate with Network, Systems, Presales, Project Management, and other technical teams to resolve technical issues.
Work with vendors and technology partners for troubleshooting, escalation, and technical support when required.
Follow change management, security, and IT best-practice procedures.
Participate in customer meetings, technical discussions, and troubleshooting sessions when required.
Support security audits and compliance-related activities.
Ensure proper documentation and handover of implemented solutions to the support/operations team.
Provide technical support to junior engineers and assist in knowledge sharing within the team.
Technical Skills:Network Security:
- * Good knowledge of firewall concepts, security policies, NAT, routing, and access control.
- Good understanding of VPN technologies, including IPsec and SSL VPN.
- Knowledge of IDS/IPS and network security monitoring.
- Understanding of network segmentation, VLANs, DMZ, and secure network architecture.
- Knowledge of authentication concepts such as RADIUS, TACACS+, LDAP, and Active Directory integration.
- Understanding of high availability (HA) and firewall clustering concepts.
- Basic knowledge of SIEM and security event monitoring is preferred.
Networking:
- * Strong understanding of TCP/IP and OSI models.
- Good knowledge of routing and switching.
- Experience with VLANs, STP, DHCP, DNS, NAT, and ACLs.
- Knowledge of routing protocols such as OSPF and BGP is preferred.
- Ability to troubleshoot network connectivity using tools such as Ping, Traceroute, Wireshark, and packet captures.
Security Technologies / Vendors:Experience with one or more of the following is preferred:
- Fortinet
- Palo Alto Networks
- Cisco
- Check Point
- Sophos
- F5
- Other enterprise network security technologies.
- Certifications:
One or more of the following certifications would be an advantage:
- Fortinet NSE / FCP
- Palo Alto Networks certifications
- Cisco CCNA / CCNP Security
- Check Point certifications
- CompTIA Security+
- Other relevant network or cybersecurity certifications.
Requirements:
- * Bachelor's degree in computer science, Information Technology, Computer Engineering, Communications Engineering, or a related field.
- 2–3 years of relevant experience in Network Security.
- Hands-on experience with enterprise firewalls and network security solutions.
- Experience in troubleshooting and implementing network infrastructure and security solutions.
- Experience working in system integrator, managed services, or customer-facing technical environments is preferred.